nesto Logo

nesto

Cyber Defence Director

Posted 3 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in Canada
Expert/Leader
Remote
Hiring Remotely in Canada
Expert/Leader
Leads and matures the cybersecurity operations function, including incident response, detection engineering, log governance, threat hunting, vulnerability management, purple-team testing, and security tooling. Manages security professionals, SOC/MSSP providers, and high-severity incident escalations while partnering with Legal, Privacy, Fraud, executives, and risk committees to improve organizational cyber defense.
The summary above was generated by AI

Join nesto — proudly named Canadian Rocketship 2025*. A Deloitte Fast 50 company evolving alongside Canada’s top tech innovators and disrupting a 2.1 Trillion-dollar mortgage industry at light speed by building the mortgage ecosystem of the future.


BUILD lending technology with the best developers, AI engineers, and mortgage experts in the country. Work on a modern tech stack and a development framework designed to unlock your full potential and accelerate your career.

Why join us
  • Hypergrowth: Deloitte Fast 50 — 3 years in a row
  • Tech community credibility: TechTO Canadian Rocketship 2025*
  • Industry leadership: CLA Lending Company of the Year — 4 consecutive years
  • Talent magnet: CMP Top Mortgage Employer 2025
  • Trusted technology: powering major financial institutions across Canada
  • An entrepreneurial culture built on trust, speed, uncomfortable ambition, being stronger together, and a relentless obsession with our clients.

About the role 

We're looking for a cyber defence leader to lead our security operations team and continue to grow our cyber defence practice alongside it. This is a hands-on leadership role for someone who can build operational excellence in detection and response while also elevating our security program's maturity through proactive testing, risk management, and cross-functional collaboration.


Your day-to-day in that role : 

  • Mentor, and develop a team of security professionals, defining career paths and skill development plans, and fostering a culture of excellence, curiosity, and continuous improvement.
  • Own the full incident response lifecycle: triage, scoping, containment, eradication, recovery, and post-incident improvement.
  • Act as senior technical and operational escalation point during high-severity incidents, partnering with Legal, Privacy, Fraud
  • Own detection engineering, converting incident observations into higher-fidelity detections, tuning opportunities, and response automation.
  • Own log source governance: telemetry coverage across our systems, periodic reviews as the environment and partners change, and log volume managed against detection value.
  • Keep detection and response at machine speed as nesto adopts AI, on both sides: our own cycle, and the agents themselves.
  • Drive continuous improvement of playbooks, enrichment, and orchestration that improve response speed and consistency.
  • Champion a purple team approach that combines offensive and defensive collaboration: attack surface analysis, threat modelling, and adversarial simulation to identify and close gaps, with threat hunting and operationalized threat intelligence feeding the work.
  • Own exposure and vulnerability management, prioritizing on asset criticality and exploitability, and driving remediation to closure with system owners.
  • Own the strategy, selection, deployment, and ongoing management of core security tooling including EDR and SIEM, keeping it tuned, integrated, and generating actionable intelligence for the team.
  • Serve as an active member of the risk management committee, translating business risk priorities into concrete defence strategies

What you bring

  • 10+ years in cyber security, including people leadership in incident response, security operations, threat investigation, or digital forensics.
  • Track record building, leading, and maturing a security operations function, including standing up new capability.
  • Proven experience leading a security operations, blue team, or incident response function, ideally in a regulated or financial services environment.
  • Deep expertise in incident response, digital forensics, EDR and SIEM platforms, threat modeling, and attack surface management.
  • Experience selecting and managing SOC / MSSP providers, including contract negotiation and ongoing performance governance.
  • Experience with a purple team or adversarial testing methodologies.
  • Strong track record of engaging with executive stakeholders and contributing to enterprise risk management programs.
  • Excellent leadership, communication, and team-building skills.

Nice to have

  • Relevant certifications (such as GCIH, GCFA, OSCP, or CISSP) are an asset.
  • AI security literacy: both AI-enabled attacker behaviour and AI-accelerated defence workflows.
  • Experience managing an MSSP
Diversity and Inclusion

At nesto, we believe that creativity and collaboration are the result of a diverse team. We are committed to fostering a culture of diversity, equity, inclusion, and belonging, and we strongly encourage women, people of color, LGBTQIA+ individuals, and individuals with disabilities to apply. We are committed to creating a workplace that is inclusive and welcoming to all.


#nestoposition

#nestocloud


Similar Jobs

11 Hours Ago
Easy Apply
Remote or Hybrid
Canada
Easy Apply
Entry level
Entry level
Cloud • Information Technology • Security • Software • Cybersecurity
Remote French-speaking Sales Development Representative responsible for researching and prospecting leads, qualifying opportunities, scheduling meetings with decision-makers, and maintaining CRM records. Requires customer-facing experience, strong account development and qualification skills, bilingual English/French, and familiarity with AI tools to enhance workflows.
Top Skills: Ai ToolsCRMSalesforce
11 Hours Ago
Remote or Hybrid
CA
Mid level
Mid level
eCommerce • Fintech • Hardware • Payments • Software • Financial Services
Build and operate ingestion and reconciliation pipelines that match card-network and partner reports against internal transactions. Develop reporting products, produce standardized journals for accounting, support tax and regulatory filing systems, handle sensitive PII for compliance, debug production issues, and collaborate with finance, product, and data teams to automate and scale reconciliation and reporting.
Top Skills: Ai ToolsAirflowAWSBigQueryCi/CdDelta LakeGoHadoopIso-8583JavaKafkaKubernetesPysparkPythonSnowflakeSparkSQLTemporalTerraform
11 Hours Ago
Remote or Hybrid
Québec, QC, CAN
Senior level
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Sell Cloudflare services to large Canadian enterprise accounts (focus Montreal). Develop and execute account/territory plans, manage complex sales cycles and contract negotiations, maintain a robust pipeline, build long-term strategic relationships, articulate technical value propositions, and ensure customer satisfaction while collaborating with internal teams.
Top Skills: CloudflareComputer NetworkingCybersecurityDnsIaasPaas

What you need to know about the Toronto Tech Scene

Although home to some of the biggest names in tech, including Google, Microsoft and Amazon, Toronto has established itself as one of the largest startup ecosystems in the world. And with over 2,000 startups — more than 30 percent of the country's total startups — Toronto continues to attract new businesses. Be it helping entrepreneurs manage their finances, simplifying business operations by automating payroll or assisting pharmaceutical companies in launching new drugs, the city's tech scene is just getting started.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account